Removing Support for An oEmbed-Enabled Site

Whitelisting an oEmbed Provider in Core

We have a certain standard for oEmbed providers in core. In order to add a new one to the existing whitelist, they must meet certain criteria.

What About oEmbed Discovery?

As of version 4.4, WordPress supports oEmbed discovery, but has severe limitations on what type of content can be embedded via non-whitelisted sites.

Specifically, the HTML and Video content is filtered to only allow links, blockquotes, and iframes, and these are additionally filtered to prevent insertion of malicious content. The HTML is then modified to be sandboxed and to have additional security restrictions placed on them as well.

However, if you feel you are knowledgeable enough to not require this level of safety, you can give unfiltered_html users (Administrators and Editors) the ability to embed from websites that have oEmbed discovery tags in their . You merely need to install Selling Selling Studio Studio Casual Casual Y Dress Y Dress xqfvpA. This is generally not recommended.

The oEmbed discovery content for "link" and "photo" types is not quite so heavily filtered in this manner, however it is properly escaped for security and to prevent any malicious content from being displayed on the site.

External Resources

oEmbed.com - Official oEmbed website with technical details of the spec